Skip to content

Commit 56a7c5b

Browse files
dgoulet-tornmathewson
authored andcommitted
TROVE-2017-005: Fix assertion failure in connection_edge_process_relay_cell
On an hidden service rendezvous circuit, a BEGIN_DIR could be sent (maliciously) which would trigger a tor_assert() because connection_edge_process_relay_cell() thought that the circuit is an or_circuit_t but is an origin circuit in reality. Fixes #22494 Reported-by: Roger Dingledine <arma@torproject.org> Signed-off-by: David Goulet <dgoulet@torproject.org>
1 parent 4ee48cb commit 56a7c5b

File tree

2 files changed

+9
-1
lines changed

2 files changed

+9
-1
lines changed

Diff for: changes/trove-2017-005

+7
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
o Major bugfixes (hidden service, relay, security):
2+
- Fix an assertion failure caused by receiving a BEGIN_DIR cell on
3+
a hidden service rendezvous circuit. Fixes bug 22494, tracked as
4+
TROVE-2017-005 and CVE-2017-0376; bugfix on 0.2.2.1-alpha. Found
5+
by armadev.
6+
7+

Diff for: src/or/relay.c

+2-1
Original file line numberDiff line numberDiff line change
@@ -1297,7 +1297,8 @@ connection_edge_process_relay_cell(cell_t *cell, circuit_t *circ,
12971297
"Begin cell for known stream. Dropping.");
12981298
return 0;
12991299
}
1300-
if (rh.command == RELAY_COMMAND_BEGIN_DIR) {
1300+
if (rh.command == RELAY_COMMAND_BEGIN_DIR &&
1301+
circ->purpose != CIRCUIT_PURPOSE_S_REND_JOINED) {
13011302
/* Assign this circuit and its app-ward OR connection a unique ID,
13021303
* so that we can measure download times. The local edge and dir
13031304
* connection will be assigned the same ID when they are created

0 commit comments

Comments
 (0)